How to Fix External Email Rejection Error 554 5.7.1 Access Denied
Question details
External senders are unable to deliver messages to the organization and are receiving a bounce-back message with an access denied error.
- Product
- Microsoft 365 / Exchange Online
- Device & OS
- not provided
- Scenario
- An external user attempts to send an email to a recipient within the organization but the message is blocked by the server.
- Observed behavior
- The email is rejected, and the sender receives a Non-Delivery Report (NDR) displaying the error code 554 5.7.1 Access Denied.
Ensure you have administrative credentials for your Microsoft 365 or Exchange admin center, as resolving this issue requires checking organization-level mail-flow rules and running message traces.
Run a Message Trace and Update Mail-Flow Policies
Use the Exchange Admin Center to trace the rejected message, identify the blocking restriction, and adjust your organization's mail-flow settings.
Error 554 5.7.1 typically indicates that an organization-level policy—such as a strict mail-flow rule, recipient restriction, or blocked sender list—is preventing the email from being delivered. It is rarely related to mailbox storage limits.
Sign in to the Microsoft 365 admin portal with your administrator credentials and navigate to the Exchange Admin Center.
In the left-hand navigation menu, go to 'Mail flow' and select 'Message trace'.
Enter the email address of the external sender and the internal recipient. Set the time range to cover when the rejection occurred, then click 'Search'.
Open the trace details for the failed message. Review the complete NDR to identify exactly which mail-flow rule, connector issue, or recipient restriction triggered the block.
Based on the trace results, navigate to the relevant settings (such as Mail flow > Rules, or Recipients > Mailboxes > Delivery restrictions) and modify the policy or add the sender to the allow list to permit future emails.

Upgrade Your Document Productivity with WPS Office
While resolving Microsoft 365 email delivery issues requires admin access, you can independently boost your daily productivity with WPS Office. As a free, lightweight, and powerful alternative to Microsoft Office, it handles all your document, spreadsheet, and presentation needs with perfect compatibility.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install WPS Office: Run the downloaded setup file and follow the simple on-screen instructions to install the suite.
- 3. Open Your Documents: Launch WPS Office to instantly view and edit your existing .docx, .xlsx, and .pptx files without formatting issues.

Frequently Asked Questions
What does email error code 554 5.7.1 mean?
This error code indicates that the recipient's email server actively refused to accept the message due to a security policy, mail-flow rule, or strict delivery restriction set by the receiving organization.
Can an individual user fix the 554 5.7.1 Access Denied error?
No. This error is caused by server-side policies and configurations. It requires a Microsoft 365 or Exchange administrator to resolve by adjusting the organization's mail-flow rules or connectors.
Why are only external senders getting this bounce-back message?
This usually happens when the internal recipient's mailbox is configured to 'Require that all senders are authenticated', meaning it will only accept emails from users signed into the same tenant or organization.
How long does it take for mail-flow rule changes to take effect?
Once an administrator updates a mail-flow rule or delivery restriction in Microsoft 365, it typically takes 15 to 30 minutes for the changes to propagate across the Exchange servers.




